Link following in macOS - CVE-2025-31182
Published: April 2, 2025
Vulnerability identifier: #VU106872
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-31182
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local application to gain delete arbitrary files on the system.
The
vulnerability exists due to insecure symbolic link following in libxpc. A local application can delete files from the system it does not have access to.
Affected software
macOS
visionOS
watchOS
tvOS
Apple iOS
iPadOS
visionOS
watchOS
tvOS
Apple iOS
iPadOS
How to mitigate CVE-2025-31182
Install updates from vendor's website.
macOS - addressed in versions 15.4 24E248, 13.7.5 22H527, 14.7.5 23H527
visionOS - update to 2.4
watchOS - update to 11.4
tvOS - update to 18.4
Apple iOS - update to 18.4 22E240
iPadOS - update to 18.4 22E240
visionOS - update to 2.4
watchOS - update to 11.4
tvOS - update to 18.4
Apple iOS - update to 18.4 22E240
iPadOS - update to 18.4 22E240
External References
Related Security Bulletins
- Multiple vulnerabilities in macOS Sequoia
- Multiple vulnerabilities in macOS Sonoma
- Multiple vulnerabilities in macOS Ventura
- Multiple vulnerabilities in Apple watchOS
- Multiple vulnerabilities in Apple tvOS
- Multiple vulnerabilities in Apple iOS 18 and iPadOS 18
- Multiple vulnerabilities in Apple visionOS